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When comparing quantum states to each other, it is possible to obtain an unambiguous answer, 
indicating that the states are definitely different, already after a single measurement. In this pa- 
\Q , per we investigate comparison of coherent states, which is the simplest example of quantum state 

comparison for continuous variables. The method we present has a high success probability, and is 
experimentally feasible to realize as the only required components are beam splitters and photon 
£N) , detectors. An easily realizable method for quantum state comparison could be important for real 

applications. As examples of such applications we present a "lock and key" scheme and a simple 
scheme for quantum public key distribution. 
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PACS numbers: 03.67.-a, 03.67.Dd, 42.50.-p, 03.65.Ta 



INTRODUCTION 



The generation, manipulation and measurement of individual quantum objects has become everyday practice in 
the laboratory. Many experiments have proven that we have the technological means to perform a wide range of 
manipulations, which, just after the advent of quantum mechanics, one could only dream of. 
t-H ' Because of fundamental differences between classical and quantum objects, certain operations cannot be performed 
. in the quantum domain at all, or they can be performed only with a fidelity less than one. The list of such operations 
is already quite long, including for instance cloning and entangling. Neither of these processes can be performed 
perfectly unless we know the initial state (or which set of orthogonal states the initial state belongs to) . Such operations 
are universal, in the sense that we are aiming at performing a transformation or manipulation of the quantum object, 
Oh! independent of the exact form of the input. Another example of such a universal process would be state comparison. 
+1> ■ We can ask whether two given (pure) quantum states are identical or not. If no a priori information about the states 
is available, we have to limit ourselves to looking at the inherent symmetry of our two particle system with respect to 



permutation. The total state for two identical quantum states is always symmetric, and therefore asymmetry is the 
unambiguous indicator of dissimilarity. 

Comparison of unknown as well as completely known quantum states has been analyzed in detail 0, 01 0, @ , as well 
as comparison of unitary transforms [(|. Not much attention, however, was paid to cases where partial knowledge 
about the possible states on which the comparison should be performed is available. In the present paper we wish to 
concentrate on this particular case. We choose to look at comparison of coherent states. The unknown parameter in 
the states to be compared is the coherent state amplitude a, specified by two numbers - its absolute value and its phase 
0- The reason for choosing coherent states is that they are easy to generate and convenient to use. Another aspect 
is that present sug gest ions for realizing quantum comparison either require non-trivial components (CNOT gates as 
in the swap test [ijOil) or destroy the states to be compared (multiport implementation of universal comparison y]). 
Coherent states, on the other hand, may be compared non-invasively, using only linear optics and photon detectors, if 
they are identical (meaning that they are equal both in phase and in amplitude). In the following we discuss not only 
the question of comparing two or more coherent states to each other, but we also analyze two possible applications. 
We present a simple "lock and key" scheme and a public key distribution scheme using coherent state comparison as 
an essential ingredient. 



II. COMPARISON OF COHERENT STATES 



Two coherent states 



Let us first see how to determine whether two Glauber coherent states \a) and \(3) Q are different from each 
other. A coherent state is a state for which a\a) = a\a), where a is the annihilation operator for the concerned 
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FIG. 1: The beam splitter mixes the two input fields in a linear way into two output fields. The relations between input and 
output creation operators are expressed in Eq. (1). 



electromagnetic field mode. Here we have no knowledge of the amplitude or phase of a and 3, but we do know that 
the states are coherent. The two states can be compared using a 50/50 beam splitter in the following way. It is well 
known, that if two coherent states |a) and \8) are incident on a balanced beam splitter, as shown in Fig. ^ then the 
output states will be \(a + 8)f\/2) and |(q — /3)/\/2) @- This follows since the beam splitter relations between the 
input and output creation operators are 
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Using these relations, we can confirm that the coherent states \a) and \0) transform as 
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If a and 8 are equal, output mode b will contain only the vacuum. Therefore, if we detect any number of photons in 
this mode, we can be certain that a and 8 cannot have been identical both in phase and amplitude. We have of course 
assumed that there are no dark counts in the detectors. If the probability for dark counts is non-zero, we cannot 
anymore infer with certainty that a and 8 were different. Detector inefficiency is not as crucial as dark counts. An 
efficiency less than one will of course degrade the probability of detecting a difference, but will not prevent us from 
drawing the conclusion that a and 8 must have been different. This is because each detector click in output mode 6, 
which is not a dark count, is a valid indicator of difference between the input states. If some of photons in output 
mode b are not detected, this will decrease the efficiency of difference detection, but does not make it impossible to 
infer that a ^ 8. 

The success probability of detecting a difference between a and 8 is equal to the probability to detect at least one 
photon in output mode b, where we have the coherent state |(a — 0)/V2). As the probability to detect zero photons 
in this mode is p(0) = exp(— l/2|a — 8\ 2 ), the success probability is 
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The success probability increases exponentially to its maximum value of 1 as shown in Fig. [5] 

A nice feature of this method is that we do not need to place any detector in output mode a. This means that 
we can again split the state in output mode a, \(a + /3)/a/2), with a second 50/50 beam splitter, giving the output 
| (a + 8)/2)\{a + 8)/ 2). If no photons were found in mode b, and a and 8 were indeed equal both in phase and 
amplitude, we recover the original states undisturbed. The fact that the states emerge undisturbed indicates a non- 
demolition aspect of the state comparison procedure, which could be useful for applications where quantum state 
comparison is needed. It should be pointed out, however, that if no photons are detected in mode b, we cannot 
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FIG. 2: The success probability of comparing two coherent states as a function of the absolute value of the difference between 
the coherent states amplitudes, \a — f3\. The knowledge that we deal with an a priori known class of states enables us to reach 
the ideal limit of 1. 




actually be sure that the coherent states were really identical. If they are not, and the output state is again split by 
the second beam splitter, the resulting states will differ from \a) and |/3). They will both be equal to \(a + /3)/2). 

In a similar way, if we choose to detect photons in output mode a instead of b, we can conclude that a and — (3 
cannot have been identical. The success probability for this is p' succ = 1 — exp(— \a + [3\ 2 /2). No matter in which 
output we detect one or more photons, a detector click will give us information about the input states. If we know, 
for instance, that \a\ — \/3\, the detector clicks will give information about the relative phase S of a and /3. Using the 
just described method, we obtain the success probability 
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This result indicates, that if the phase difference is large, moderate coherent amplitudes are already sufficient to 
yield a high success probability for the comparison test. For small phase differences, this is possible only for large 
amplitudes. To obtain a sufficient success probability, the phase difference should scale according to S rs c/a, where 
c is a constant, and a is the coherent state amplitude. Hence the comparison strategy does not offer any particular 
advantage when searching for optimal phase measurements |Tlj . 

Finally, we could instead use a beam splitter which is not balanced, but has different transmission and reflection 
coefficients T and R. In this case, the output state is given by \\/Ta + \/R/3) ® \V~R~a - \/T/3). Finding photons 
in the first output mode determines that y/Ta + y/~R(3 ^ 0, and photons in the second output mode means that 
y/Ra — Vrp ^ 0. With phase shifters before the input ports of the beam splitter, we can more generally test whether 
\/Te i6 a + y/R/3 ^ 0. 

We can also compare the success probability (0 with the success probability for the universal comparison strategy. 
If we want to compare two general pure quantum states \<j>) and but we have no information about the states, 
the best we can do is to check whether the overall state \<f>) (g> \tp) is symmetric with respect to permutation or not 
Q,0|. If \4>) and \4>) are equal, the overall state is necessarily symmetric. Therefore, if the state is found not to be 
symmetric, we can be sure that the states were not equal. The success probability is the probability of finding the 
states in the asymmetric subspace, which is 

Pasymrn = 1 ~ Psymm = ^(1 - | < <^> | 1 2 ) - (5) 

For the two coherent states, this success probability becomes 

Pasyjrun 9^ ^ ^ ^' 

The success probability @ for the coherent state comparison is larger than that of the optimal universal comparison 
strategy, since 
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with equality only when both probabilities are zero, i.e. when a = f3. We are able to obtain a "better than optimal" 
success probability since, in the above beam splitter scheme, we made use of the additional knowledge that the states 
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FIG. 3: The balanced multiport is a passive device distributing an incoming photon with equal probability among all the 
outputs. The device can be constructed using beam splitters and phase shifters. 



are coherent. If we would not have this knowledge, we would have to revert to the universal comparison strategy. 
The success probability of the optimal universal strategy is always below 1/2, whereas when \a — f3\ becomes large, 
the success probability of the beam splitter strategy approaches one. This reflects the fact, that when \a — (3\ is large, 
we enter the classical regime. Here we have not addressed the question whether the beam splitter strategy is optimal 
for coherent states. It certainly has the appealing feature that it is easy to implement experimentally, which is very 
important. 



B. Comparing squeezed vacua 

Squeezed vacua may also be compared to each other using a beam splitter. A beam splitter transforms two squeezed 
vacua s\ exp(£ia^)|0) and s 2 exp(^2^j^)|0), where si and s 2 are normalization constants, according to 

SlS2 exp(£ia^ + &S£)|Q) = Sl s 2 exp{i[£i(aL + + 6(«L - &L) 2 ]}|0> (8) 

= Sl s 2 exp[i(£i + + bfut) + (6 ~ 6)«L&L]|0). 

From this expression, we see that when £i = £2, both output modes will contain only even numbers of photons. 
Detecting an odd number of photons in either of the outputs (assuming perfect detectors) therefore indicates that 
£1 7^ £2- Correspondingly, detecting an even number of photons indicates that £1 7^ —£2- The expression for the 
probability to detect an odd number of photon is rather cumbersome. It takes the explicit form 

min{l,m} , _ t \k ( (gi±|g) \2l+l-k 
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Counting photons is more demanding experimentally than not resolving photon numbers, but photon chopping [l2] | 
as realized by a time resolved multiport splitter 01 ma y be possible, and could be used at least for small photon 
numbers, implying that the weakly squeezed states could be compared. In the following we will limit our considerations 
to coherent states. 



C. Several coherent states 



The beam splitter method of comparing two coherent states can easily be generalized to more than two states. For 
this we need to use a balanced multiport (see Fig. 3), effecting the transform 
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where a\ are now the creation operators for the N input modes and b\ are the creation operators for the output 
modes. The elements u k i of the transformation matrix of the balanced multiport are given by 

1 2irikl 

u u = _exp(-^), M = 0,1,..., JV-l. (11) 

We may also think of this as a discrete Fourier transform. The TV coherent states \ao) <S> |cki) ® ■■■ <8> |ajv-i) will 
transform as 
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If all aj are equal, only the zeroth output mode will contain any photons. All the other modes will contain vacuum, 

since X^=o u lk = unless fc = 0. Therefore, if any photons are detected in any of the modes 1 to N — 1, all the 
coherent input states cannot have been identical. The probability of detecting zero photons in the fcth output mode 
will be 

JV-l 

p k (0)=cxp(-\J2^ k \ 2 )- (13) 

1=0 

The probability to detect no photons in any of the output modes 1 to N — 1 is 

p(0)=pi(0)p 2 (0)-...-p JV _i(0) ) (14) 

and the success probability will thus be 

JV-l JV-l 



Psucc = 1 - p(0) = 1 - exp(- Y I E a i u *ik\ 2 ) 
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where the second line is obtained after a straightforward and not too lengthy calculation. An alternative way of 
writing the success probability is 




(16) 

This success probability will again always be larger than that of the optimal universal comparison strategy; this 
statement is proved in an appendix. 

The multiport setup does not only give knowledge of when all the coherent input states are not identical. Detection 
of photons in output mode fc means that the sum 

JV-l 

E a << 

1=0 

must be nonzero. Conversely, if a/ = \a\^/Nu ik for some fc, then output mode fc must be the only mode containing 
photons. Detection of a photon in any other mode than mode fc indicates that ai ^ \a\\/Nuik for at least one a;. 
Setting fc = we again obtain comparison, i.e. a test whether all a>i are nonidentical. 
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Although the experimental realization of a balanced multiport for large N is nontrivial, the suggested scheme should 
be feasible to implement for small N. A multiport may be built up using 2x2 beam splitters 01 > alternatively a 
fiber coupler could be used, at least for N = 3 It might be also possible to use the time-resolved realization of a 
multiport that we already mentioned in connection with photon counting |13| . 

D. States which will always pass the comparison test 

In the quantum state comparison schemes for two or more coherent states and for squeezed states proposed above, it 
is guaranteed that if the input states are identical and of the required form, then they will always pass the test. There 
are, however, also other quantum states which are guaranteed to pass the test, even if they are not coherent or squeezed 
states. The same situation arises also for universal quantum comparison 0,0- 

There, in order to compare the states, 

we test whether the total state is symmetric or not. Therefore, any total state which is completely symmetric will 
always pass the universal comparison test, even if the states of the individual quantum states may not be the same. 
For two quantum systems, this would be any state of the form l/v / 2(|0)|V') + |V')|0))- This can be easily generalized 
to universal quantum comparison of more than two states. 

When comparing two coherent states, we associate photons detected in output mode b with the input states being 
different. Any input state, which results in photons exiting only in mode a, will always pass the comparison test. It 
follows, that a complete basis for the input states which will always pass the test, is given by evolving the number 
states |n) a |0)b backwards through the beam splitter. The input states take the form of SU(2) coherent states, which 
are entangled, 

\^n) = ^£^\n-k) a \k) b . (18) 

These states, as well as linear combinations and mixtures of them, will always pass the comparison test. For comparison 
of many coherent states, a complete basis for the states which will always pass the multiport test is likewise given by 
evolving linear combinations of the number states |n)o|0)i|0}2---|0) jv— l back through the multiport. 

As for quantum comparison of squeezed states, the corresponding states are obtained by evolving number states 
\fn)a\n)b, where m and n are even, back through the beam splitter. A basis for the input states which always would 
pass the squeezed state comparison is given by the states 

|^„) = -j=±-^= (™) (?) (-l)W(rn + n-k-l)[y/{kTt)i\m + n-k- l) a \k + l) b . (19) 

These states are again entangled states of the input modes. Linear combinations of, and statistical mixtures of these 
states (and statistical mixtures of linear combinations of these states) will always pass the comparison test for squeezed 
states. 

Next, we analyze two simple quantum cryptographic protocols where quantum state comparison of coherent states 
is needed. The first scheme, denoted as a quantum "lock and key" scheme, is based on the seminal work of S. 
Wiesner |l6j , which sparked the field of quantum cryptography. The second example we consider is based on ideas 
for public- key cryptography. More precisely, we introduce a protocol to distribute and test quantum public keys. 

III. A QUANTUM "LOCK AND KEY" SCHEME 

In his original proposal, S. Wiesner showed how to use quantum- mechanical systems in order to create a secret 
key that is impossible to counterfeit, but which can be validated by means of a lock 16]. The main idea behind this 
scheme is to use, as a secret key, a sequence of M quantum systems, each one prepared in a state that is selected, 
randomly and independently, within a given set of N non-orthogonal quantum states. Here we will consider a set 
of non-orthogonal states composed only of coherent states \(Xj), as we have in mind the experimental realization 
described in the previous section, i.e., 

\tpkey) = \ai) ® \a 2 ) ® ... ® \a M ). (20) 

Each quantum key \ipkey) is associated with a unique quantum lock state \ipiock), composed of an identical string 
of coherent states, i.e., \ipiock) = \i^key)- In order to check if a given key is valid and opens the lock, one needs to 
compare the key string with the lock string. All the key states must match the corresponding lock states, or more 
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precisely, none of the key states may be detected as different from the corresponding lock state. As a result, a possible 
adversary who is ignorant of the key states has absolutely no way of counterfeiting them faithfully. 

Note that this protocol could just as well be implemented by using a classical lock instead of a quantum lock. In 
this case, the lock would contain a classical record of the actual states in the key string. Now, in order to test whether 
the key fits in the lock, one can measure each state in the key string, projecting it onto the projectors \cej}(aj\ and 
1 — \otj)(otj\. This measurement can be effected using the classical record of the state \tpkey), which is stored in the 
lock. Quantum comparison of two unknown quantum states would not be needed in this scenario, only measurements 
performed on single quantum states. The version where the lock contains no classical record, but only the quantum 
states \aj), has, however, the advantage that in this case, it is impossible for an adversary to make new perfect key 
copies based on the information stored in a lock. 

We will assume that all the coherent states \ctj) included in the key have the same amplitude |a|, while the phase 
of each individual state is chosen randomly and independently as 2irk/N, where k £ (0,1,2, N — 1), with equal 
probability for each k. Other choices are of course possible. Next, we analyze, in more detail, the security of this 
"lock and key" scheme against a possible adversary with unlimited quantum computational power. 



A. Forcing the lock open without a key 



An adversary who does not have a key, and who does not know the phase of each individual a>j , could still try to 
open the lock. We will assume that the information about the amplitude \a\ is public. The adversary is not limited 
to using coherent states in order to try to counterfeit a key, but can prepare any general quantum state, where the 
states of the individual positions might be entangled. Note, however, that since the phases of the coherent states in 
each lock position are random and uncorrelated, and the comparison test is performed for each position of the lock 
string individually, he or she cannot get any advantage from using entangled states. Assuming that the states in the 
individual key positions are not entangled, then, for each position in the key, the adversary can prepare a general 
state f^d 2 /?P(/?)|/?)(/?|. Here d 2 (3 = f^f^dPrdfa, with r = Re/3 and & = Im/3, and the adversary is 
choosing P(/3) so that the probability to pass the comparison test is as high as possible. P(/3) is the P-function 
of the state, and any state can be written in this way with a suitably chosen (albeit sometimes highly singular) 
P-function. The probability for the false key state to pass the comparison test with the lock state in one position, 
which is |(Xj) = ||a|e 4e '), is, on average, 

p pass = 1 - Psucc = ^ J dOj d 2 pP(P)cxp(--\\a\e t9 -P\ ), (21) 

where we integrate over 9, since the phase 9 is chosen randomly with a uniform distribution, and the adversary does 
not know the phase, only the amplitude, of ctj. For simplicity, the number N of possible phase angles is infinite in 
the expression above, but one could also calculate p paS s for a specific N. In a real protocol, N should, in any case, be 
large. The adversary wants to maximize the probability p paS s ■ Writing — \(3\e tef3 , and assuming that we can switch 
the order of integration, we obtain 

Ppass =2^J d9 J ^WW^IM^ -\P\e ie e\) 

-I /*00 flit 1 

= ^J d 2 pP(p)J^ ^cxp[--(| a | 2 + |/3| 2 -2|a/3|cos(0-^))] 

d 2 (3P(P) ex P [-i(M 2 + |/3| 2 )]/ (l«/3|), (22) 



/ 

j — ( 



where the function 7 (|a/3|) = ^ d9 exp(|a/3| cos#) = ^ J 27r eft? exp[|a/3| cos(6* — 9p)\ is a modified Bessel function 
of the first kind. It turns out that, for a < y/2, p paS s is maximized if we choose P{]3) = (5(0), that is, the best false 
key state is a vacuum state and the maximum probability to pass the comparison test is given by 

Ppass = exp(-i|a| 2 ). (23) 

For a > \/2, the maximum probability to pass occurs if the adversary chooses \(3\ closer to \a\, but still with \(3\ < \a\. 
For large values of \a(3\, Io(\oe(3\) ~ el Q/3 l /y/2n\a/3\, and therefore 

exp[-i(H 2 + |/3| 2 )]/ (|«/3|) ~ -^=exp[-i(|a| - |/?|) 2 ]. (24) 
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Therefore, for large a, the adversary should choose |/3| ~ |a| to maximise the probability to pass the comparison test. 
This probability will decrease as a function of a approximately as 

Ppass ~ J- . (25) 
V27T \a\ 



For a key string containing M coherent states, the probability for a false key state to pass the comparison test for 
all M positions is p^ ass , so that the probability decreases exponentially with M . As long as a is not too small, we 
find that the probability of the adversary successfully cheating is severely restricted. In addition, if the total average 
number of key and lock photons at the output is measured (or the number of key photons is measured directly at the 
input), then any cheating strategy where a false key state contains the wrong average number of photons would be 
discovered. 



B. Obtaining information about a key 

Let us now suppose that an adversary has access to one valid copy of the key, and that he or she tries to extract 
information from it. Of course, it is clear that once an adversary has a valid key, then this key can always be used 
to open the lock. But if a key copy is missing, this may be noticed by the rightful owner of the key. Obtaining a 
full classical description of the quantum state of the key, on the other hand, would allow the adversary to prepare as 
many valid keys for a given lock as he/she wishes. In particular, the adversary could make one copy for returning to 
the rightful owner, so that it is perhaps not noticed that a key copy has been stolen, as well as extra "illegal" key 
copies. We will now show that the information that can be obtained by measurements on one or more copies of a key 
is limited. 

The maximum information that the adversary can obtain by measurements on one single copy of the key string, 
called accessible information and denoted as I acc , is limited by the Holevo quantity x(Pkey)- Here pk ey — ^2 n PnPn is 
the state of the key string according to the information available to the adversary before the measurement; in other 
words, p n are the possible states of the key string, and p n their respective probabilities. The possible key states \ctj) 
in each position are given by ||a| exp(2Trik / N)} , where k takes the values 0, 1, 2, N — 1. If there are M positions 
in the key string, then, as far as the adversary knows, there are N M possible pure states p n , all cquiprobable, with 
Pn = 1/(N M ), that the total key string could have. The accessible information about which of these N M states the 
key state actually is, is bounded according to 

Iacc < X(Pkey) = S(p key ) - ^p n S{p n ), (26) 

n 

where S(pk ey ) — — Tr(pfc ey log 2 Pkey) is the von Neumann entropy of pkey The quantity J2 n p n S(p n ) is always positive 
or zero. When the different possible states p n are pure, as in our case, it is zero. 

As the M coherent states in different positions in the key string are completely uncorrelated, the accessible infor- 
mation of the whole key string is bounded by M times the accessible information for each position in the key string. 
Let us therefore look at the state in a single key position. Since the adversary does not know the phase of the coherent 
key state \cej), in this position, the density matrix according to the information available about the state prior to the 
measurement is 

i 

/We = jj £ \ae ik2 «/ N )(ae ik2 */ N \. (27) 

k=0 

For this state, the von Neumann entropy, which limits the accessible information since the different possible states 
are pure, can be found to be 

JV-l 

S{Psin g le) = £ JJ^T lo S 2 (^0 (28) 
m =0 lyJX rn 

where 

N-l 

K m 2 = cxp{-H 2 [l - cxp(ik2i:/N)} + imk2n/N}. (29) 

fe=0 

When \a\ = 0, p S ingie = |0)(0|. As there is only one possible state, the information stored in the key state is zero 
in this case. The von Neumann entropy and the accessible information for the key state are also zero. For a useful 
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FIG. 4: The von Neumann entropy as a function of the mean photon number |a| 2 for N = 2,3,4,5,6. The asymptotic value 
of the entropy increases with the number of states N. 

key scheme, we need to choose \a\ larger than zero, but not too large, for a given number of states N. For instance, 
when the amplitude \a\ goes to infinity, the accessible information for each key position approaches log 2 N, which is 
the information that can be obtained from N distinguishable states, or from N classical states. This reflects the fact 
that, for larger |a|, the N possible key states become more distinguishable. A coherent state with a larger amplitude 
becomes more "classical" . In Fig. the von Neumann entropy, which bounds the accessible information, is plotted 
as a function of \a\ 2 for some values of N. 

We should choose the amplitude \a\ small enough, and N large enough, for the accessible information not to be too 
large compared to log 2 N, but \a\ large enough for the probability to detect a difference in the key and lock states to 
be sufficiently large. In particular, as we have seen that the best false key state is a vacuum state, we have to adjust 
| a | so that there is a reasonable probability to detect this cheating strategy. As we saw previously, the probability to 
detect a difference in key and lock can also always be increased by increasing the length M of the key string. 

When N goes to infinity, the state in equation Ij27(l becomes a phase-randomized state, which is diagonal in the 
number state basis and can be written as 

&e=e-H 2 £M_| fc)(fc |. (30 ) 

k=0 

The von Neumann entropy for this state is 

00 I 1 2 / I \2k \ 

S(p- ngle ) = H 2 - e-^ £ M_ log2 m\ . (31) 

k=0 ' V • / 

As before, this quantity also bounds the accessible information. We can obtain an approximation for this expression 
using the Stirling formula for the factorial. The result takes the rather simple form 

9 J « log 2 (27re|a| 2 ). (32) 

The entropy increases in a logarithmic way with the coherent state amplitude \a\. 

Till now, we have considered a "lock and key" scheme where only one single copy of each key may exist. However, 
it is possible to design a protocol which uses as many copies of the key as we like. The security of the scheme will 
necessarily decrease with the number of key copies. An adversary wanting to fabricate illegal key copies could get 
hold of all the keys in circulation, and using these, will be able to fabricate a better false key than if just one or very 
few key copies are in circulation. However, the information an adversary can obtain per key copy is still limited by 
the Holevo bound. If it is possible to obtain at most K bits of information about the state in one position of the key 
when one copy is available, then at most TK bits can be obtained if T copies are available. In this last case, we need 
to guarantee that log 2 N ^S> TK. 

Finally, let us briefly mention that the adversary might try to make a copy of the single existing key. For this, he 
would need to make a clone of each individual coherent state. This is only possible with a certain degree of fidelity, 
as making perfect copies is forbidden by the no-cloning theorem. We should, however, bear in mind that we do not 
deal with completely unknown states but with a know class of states - large enough amplitude coherent states can 
be copied almost perfectly. Cheating by this method can, however, be prevented by choosing a long enough string of 
states, or by choosing N large enough. 
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IV. QUANTUM PUBLIC KEY DISTRIBUTION 

Public key cryptography requires two keys — the public key and the private key, which form a key pair. The sender, 
usually called Alice, generates the key pair, makes the public key public and keeps her private key in a secret place 
to ensure its private possession. The key generation algorithm is designed in such a way that anyone having a public 
key can, for instance, use it in order to encrypt a message for Alice (public key encryption schemes), or certify that a 
message originates from Alice (digital signature schemes). However, only Alice can decrypt or sign a message using 
her private key [l7j . 

Unfortunately, the security of classical public key cryptography rests on unproven assumptions related to the 
intractability of certain difficult mathematical problems. The key generation algorithm utilizes so-called one-way 
functions to guarantee that the public keys do not reveal information about the private key. This kind of mathematical 
functions are easy to evaluate in one direction, but their inverse is very difficult to compute [l8llT^ |. However, these 
computational assumptions may be defeated by exhaustive computer analysis, or by the discovery of better algorithms 
for solving the problems on which they are based. If a quantum computer is ever built, many classical public key 
cryptosystems in use today will become unsafe, leading also to a retroactive security break [2(j . 

Quantum-mechanical systems can be used to create one-way functions which are provably secure from an 
information-theoretic point of view. For instance, one can obtain a quantum one-way function by defining a quantum 
map T : k G {0, 1}" — + \^k)i whose input is a classical n-bit string k, and whose output is a quantum state \ipk) 
|lOj |. As in the previous section, we will here consider that \ipk) is of the form \ipk) = la*) ® \a\) ® ••• \oi%[), where 
the state of each coherent state \oq) belongs to a given public set of N possible coherent states. In this case, we 
have that n = M log 2 N. The impossibility of inverting the function T can be guaranteed by means of the Holevo 
bound, which limits the amount of classical information that can be extracted from a quantum state. In particular, 
and assuming that there are T copies available of each public key \ipk), we find that an adversary can obtain, at most, 
TS(p pu tiic) bits of information by measuring all the copies of the public key, where p pu biic — l/(-^ M )Sfc IV'fcXV'fcl 
represents the state of the public key according to the information available about it before the measurement, and S is 
the von Neumann entropy. That is, if we assure that n = Mlog 2 N 3> TS(p pu bii C ), then the probability of successfully 
guessing the classical private key k, given all the public keys, remains small. Note that in the case of quantum public 
keys, this means that only a limited number T of them can be in circulation to guarantee unconditional security. 

Next, we present two possible schemes that use balanced multiports to securely distribute quantum public keys. 
The first scheme assumes the availability of a trusted key distribution center which has authenticated links |2l| to 
all the participants. In the second scheme, we consider the scenario where all the recipients obtain their public keys 
directly from Alice via an authenticated quantum channel, and no trusted key distribution center is available. We 
study the security of both schemes against two scenarios of cheating, motivated from the key distribution phase which 
is needed in the quantum digital signature scheme introduced in Ref. |10|. For simplicity, in the security analysis we 
will consider the case where there are only two recipients, called Bob and Charlie. The extension to a higher number 
of recipients is straightforward. In the first cheating scenario, only Alice is dishonest; her objective, once the public 
key distribution phase is completed, is to get Bob and Charlie to disagree about the validity of the private key when 
this key is revealed. In a digital signature scheme, this case corresponds to Alice trying to repudiate the signature of 
a message with her private key. In the second cheating scenario, Alice and at least Bob are honest, while Charlie can 
be dishonest. The goal of Charlie is to make Bob accept as valid a false public key that does not come from Alice, 
but comes from Charlie. This corresponds to the standard forging scenario. Note that Charlie could always prevent 
Bob from receiving any public key coming from Alice just by cutting the line, but we do not consider this to be a 
success for the cheaters. 



A. Public key distribution with trusted center 

The goal is to generate and distribute T copies of the quantum public key \ipk) selected by Alice. One straightforward 
solution in order to do this is to assume the existence of a trusted key distribution center composed by M balanced 
multiports with T inputs each. Alice prepares and sends to the key distribution center the quantum state \^) = 
\VTai) (8> \VTct2) (g> ... ® \^/Ta k M ) as a starting point for generating the public keys. Once this state is received by 
the trusted center, each coherent state \VTctj), with j = 1...M, is used as one input for the jth balanced multiport, 
while the remaining T — 1 inputs of each multiport contain vacuum. As a result, the output state of the jth multiport 
is given by \a!p)® T , i.e., it contains T copies of the coherent state \ctj). Combining all the output states of the M 
multiports in the trusted center one obtains the state \ipk)® T ■ To conclude, the trusted center sends each receiver one 
copy of the public key \ipk) through an authenticated quantum channel. 

Let us now analyze the security of this public key distribution scheme according to the cheating strategies introduced 
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above. A reader who is not interested in the security proof may go directly to Sec. IIVBI Since each public key \ipk) 
is sent to each receiver via an authenticated quantum channel established with the trusted center, it is clear that a 
dishonest Charlie cannot make Bob receive a false public key. We need, therefore, to consider only the case where 
Alice is dishonest. That is, we have to evaluate the probability of Bob and Charlie to disagree about the validity of 
the private key after using the public key distribution scheme introduced above. Here we consider the case where the 
private key is made public in a later step of the particular quantum cryptographic protocol that uses the public keys 
obtained from the trusted center |10| . Note that we are only interested in the security of the quantum public key 
distribution protocol. 

After Alice announces her private key k' (or a function of it), Bob and Charlie can compute the function T and 
obtain a classical description of the corresponding public key |Vv)- We use a different index k 1 , since Alice, or 
somebody else, could try to distribute a private key that does not match the previously distributed public key. Now, 
in order to evaluate whether k 1 is correct and originates from Alice, they can test whether the state \ipk') is equal to 
the public keys obtained previously from the trusted center. This test can be done, for instance, by projecting each 
single position j in the string of states of the public key onto the projectors \aj }(a^ | and 1 — \aj ) (a| | coming from 
the knowledge of \ipk')- Then each recipient can count the number of positions j where the measurement test provides 
an incorrect result, i.e., a result associated with the projector 1 — \a k ){oC |- We denote the number of incorrect 
results by e. 

When all the parties are honest, all the recipients obtain e = 0. If Alice is dishonest, then the quantum public 
key distribution protocol presented above cannot prevent a situation where one recipient obtains e = 0, while others 
obtain e > with high probability. For instance, Alice could send to the trusted center a quantum state {ip^}, which 
differs from \ipk') in only one position. This position could contain a coherent state \ VT(3) satisfying |(/3|a' c )| 2 = 1/2, 
where the coherent state \a k ) denotes the state of \4>k') in that position. For this simple scenario, we find that Bob 
and Charlie will obtain, respectively, e = and e = 1 (or vice versa) with probability 1/2. Moreover, note that a 
dishonest Alice is not restricted to use coherent states in order to prepare ), but she can use any general quantum 
state. What this public key distribution protocol can guarantee with high probability, however, is that if one receiver 
obtains e = 0, then no other receiver will obtain e > sM for s or M sufficiently large. Here s G [0, 1] represents a 
security parameter of the key distribution protocol. This result can be used in a cryptographic protocol, which uses 
the public keys coming from the trusted center, to guarantee the following ,1Q]. If no errors are found, i.e., e = 0, 
the recipient (e.g. Bob) can conclude that k' is correct, and he can be sure (with high probability) that any other 
recipient (e.g. Charlie) will also conclude that k' is correct. If < e < sM, Bob can, also in this case, conclude that 
the key is correct, but now he cannot be sure that a second recipient (Charlie) will not conclude that k' is incorrect. 
Finally, if e > sM, Bob can consider the private key to be incorrect, and that Charlie would either also consider it to 
be incorrect, or at least Charlie would know that Bob may conclude that k' is incorrect. 

Next we obtain an upper bound on the probability of Alice to cheat. In order to do that, let us first consider the 
following situation. Imagine that the trusted center knows the private key k' that Alice is going to declare later on, 
and, instead of distributing to Bob and Charlie the two quantum public keys coming from the multiports, he sends 
them directly the classical results obtained from measuring each of these two quantum public keys accordingly to the 
string of states contained in \4>k')- That is, he sends Bob and Charlie the classical results of projecting each position 
of the public keys onto the the projectors )(a^ | and 1 — )(<Xj |. Moreover, for each position j in the key 
string \ipk')> the results obtained from the measurements on the two public keys are distributed to Bob and Charlie 
at random. 

Note, now, that the fact that the trusted center, instead of Bob and Charlie, measures the public keys, does not 
modify the measurement statistics that Bob and Charlie would obtain in the original scenario, once k' is known and 
they perform their measurements according to \ipk')- Moreover, the random distribution of the classical results is 
guaranteed by the intrinsic random character of the multiport used by the center to distribute the states to Bob and 
Charlie. Alice makes Bob and Charlie disagree if one of them obtains e — (in absence of noise) and the other obtains 
e > sM. This means that the probability of Alice to cheat in this particular situation, p c heat, is maximized if, in 
total, the trusted center finds only sM errors in both public keys, and he sends all the errors to Bob or to Charlie. 
We obtain, therefore, 

Pcheat < (l;) SM 1 ■ ( 33 ) 

This upper bound also represents an upper bound on the probability of Alice to cheat in general. 
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FIG. 5: The setup for public key distribution without a trusted center, when there are two recipients, Bob and Charlie. Alice 
sends Bob and Charlie one copy each of her public key. In the picture, she uses a beam splitter to do this. Bob and Charlie then 
split their key copies in two using beam splitters, and exchange "key halves" with each other. They then perform comparison 
tests, indicated by the dashed circles, on their own half key copy and the one they received from the other recipient. If all 
parties are honest (and their detectors perfect), the output ports with the dashed arrows should only contain vacuum. 

B. Public key distribution without trusted center 

Let us now analyze the scenario where no trusted center is available. In this case, Alice sends one copy of the 
public key \ipk) directly to each recipient, via an authenticated quantum channel. Then, in order to prevent Alice 
from cheating, all the recipients need to collaborate to verify that all the public keys sent by Alice are equal. In order 
to do this, they use a distributed comparison test, which can be divided in two phases. Essentially, each recipient 
compares his or her public key copy with all the other recipients' copies, and, if Alice has sent different public key 
copies to different recipients, this will be detected. Neither can any of the recipients sabotage the public key copy of 
another recipient. This would also be detected in the comparison test. 

The protocol requires that each recipient has 2M balanced multiports with T inputs each. In the first phase, the 
first M balanced multiports are used to split the quantum public key sent by Alice. The case for two recipients is 
shown in Fig. [S] In concrete, each coherent state \a^) in \ipk): with j = 1, ...,M, is used as one input for the jth 
balanced multiport, while the remaining T — 1 inputs of each multiport contain vacuum. The output state of this 
multiport is given by |(l/\/r)cvf)® T . That is, it contains T copies of the coherent state \(l/VT)aj). Now, each 

recipient keeps for himself one copy of \(l/y/T)ctj), and distributes the remaining T — 1 copies of it to the other T — 1 
recipients via an authenticated quantum channel. The second phase includes a quantum state comparison test using 
the second set of M multiports. The jth multiport in this second set receives as input the coherent state \(l/\fT)a k -) 
kept by the recipient after the first phase, together with the corresponding T — 1 "copies" of it obtained from the 
other T — 1 recipients. Note that, if all the parties are honest, the zeroth output mode of this multiport will contain 
the state \oq), while all the other modes will contain vacuum. That is, combining all the output states of these M 
multiports, each recipient can recover Alice's quantum public key \rpk) perfectly. The non-demolition character of 
the quantum comparison procedure (meaning that it does not alter or destroy the compared states if all parties are 
honest, so that the compared coherent states are identical to start with) is seen to be vital for the protocol to work. 

Next, we study the situation when Alice is dishonest. A reader who is not interested in the security proof can 
go directly to the Conclusions. In principle, instead of preparing T copies of \tpk) and distributing them among the 
legitimate recipients, Alice can prepare any general quantum state, including entangled states. However, it turns out 
that, for each position j in the public key strings sent by Alice, the states that the recipients obtain as output of 
the zeroth mode of the jth multiport used for state comparison are completely symmetric under permutation. This 
means that, although Alice could in principle prepare states that make the parties disagree about the validity of the 
private key k', she cannot control which of the recipients receives the valid results. Once Alice declares the value of 
k' and the recipients project their public keys, coming from the output of the zeroth mode of the M multiports, onto 
the projectors \oq ){oq | and 1 — \oq ){oq |, the errors are distributed at random between all the recipients without 
Alice being able to control this. We can use, therefore, the same argumentation as in the previous section, to obtain 
that the probability of Alice to cheat in this scenario also satisfies Eq. 
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Finally, we need to consider the situation where Alice and Bob are honest, but Charlie can be dishonest. The goal 
of Charlie is to make Bob accept a false public key that does not match Alice's private key. Note that in this key 
distribution protocol, a dishonest Charlie can try to influence Bob's public key by means of the quantum states that 
he needs to send to Bob for the comparison test. In order to make Bob reject Alice's private key, Charlie needs to 
send him quantum states that can produce at least e > sM errors in Bob's results. However, for sufficiently large s or 
M, this situation can also be detected by Bob in the comparison test. Whenever Charlie sends Bob a state different 
from the one coming from Alice, Bob can detect this fact by finding photons not only on the zeroth output mode of 
the corresponding multiports used for comparison. 

V. CONCLUSIONS 

We have analyzed quantum state comparison for the case when one has prior knowledge about the class of states 
from which the states to be compared are chosen. We chose to look at comparison of coherent states, and have 
shown that, for large coherent state amplitudes, the probability to detect that the two coherent states are different, 
when they are indeed different, approaches one (certainty). In contrast to this, the success probability for a universal 
comparison strategy never exceeds 1/2. A universal strategy has to be used when no prior information about the 
quantum states is available. In addition to the high success probability, the quantum comparison strategy for coherent 
states has a non-demolition character - it does not destroy the compared quantum states, if they are indeed equal 
coherent states. In this case, one can recover the original coherent states unaltered. If the compared coherent states 
are unequal to start with, then they will be altered by the procedure. 

Following this, coherent state comparison was used to develop two examples of applications — a "lock and key" 
scheme and a public key distribution scheme. For both these applications, the non-demolition character of the 
quantum comparison procedure is vital. We believe that both examples are not only conceptually simple, but also of 
some practical importance due to their experimental accessibility. 
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APPENDIX A: SUCCESS PROBABILITY FOR QUANTUM COMPARISON OF TV COHERENT STATES 

In this appendix, we will prove that the quantum comparison strategy, which is tailored for coherent states, always 
has a larger success probability than the universal quantum comparison strategy, when comparing N given coherent 
states |ao), \<Xi), |qat-i)- The universal comparison strategy is a projection onto the totally symmetric, and onto 
the asymmetric subspaces. If the total state of the quantum systems is found to be asymmetric, then the states of 
the individual systems cannot all have been the same. The success probability of the coherent state strategy is given 
by Eqns. (|15|) and H16|) . The success probability of the optimal universal strategy will be 0,0] 

Pasymrn = 1 ~ Psymm = 1~ («0 I («1 1 • ■ ■ 1 Psymm | «o) I "l) ■ • • I <*N- 1 ) , (Al) 

where P sy mm is the projector onto the symmetric subspacc. We have that 

Psymm = JTj {do | («1 1 ...(aj\r_l | ^ I a *o ) K'l ) • ■ ■ I -l ) , ( A2 ) 

perm 

where the sum should be taken over all AH permutations of the indices in the kets, so that (io,ii,i2, ■•• ! ijv— l) is a 
permutation of (0, 1, 2, N — 1). As an example, for N — 3, 

Psymm = ^| ( l + I ( a I a l > ? + I ( a l \ a z) 1 2 + I («2 I «o) P 

+ (a \ai) (ai\a 2 ) (a 2 \a ) + (a \a 2 ) (ai\a ) (a 2 \ai)) . (A3) 
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To prove that the multiport strategy for coherent states always will have a greater success probability than the 
universal strategy, we will use the fact that for a collection of N numbers, their geometric mean, defined as the iVth 
root of their product, is always smaller than their arithmetic mean. Starting with the case of three coherent states, 
Psymm in equation i|A3() can be viewed as the arithmetic mean of the six terms in the parenthesis. The geometric 
mean of these six numbers is 

,1/6 




(|(aoK)| 4 |(ai|a2)| 4 |<a 2 |ao>| 4 ) ' = TT K«iK)l • ( A4 ) 



which is the probability that the coherent-state multiport scheme will fail for three coherent states. The coherent- state 
multiport scheme therefore has a larger probability to succeed than the universal quantum comparison strategy. For 
general N, the proof is similar. The quantity p S ymm in equation (|A2(I is viewed as the arithmetic mean of N\ numbers. 
To calculate the geometric mean of these numbers, we need their product. In this product, the factor (aj\a{) will 
occur (N — 1)! times, since if we choose to pair j with I, there are (N — 1)! ways to choose the rest of the index pairs. 
Therefore the geometric mean of the TV! numbers is 

)1/N\ , >. l/N 

I N-l \ 
= IJ {aMl)\ = 1 - Psucc < Psymm, (A5) 

y,z=o / 

which means that the multiport comparison strategy for coherent states has a smaller probability to fail than the 
universal quantum comparison strategy — in other words, it will always do better. 
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